Core Points
Revolut reportedly responded to false requests. Involves identity and bitcoin-related records. There have been no reported leaks of the private key. The main risk lies in targeted impersonation fraud.
The problem started with forged legal requests.
CoinDesk reported that Revolut, after contacting relevant authorities, determined that the emergency government request it had received was fraudulent and notified affected users. According to reports, the disclosure includes personal and bitcoin-related records.
The incident was not described as a situation in which an attacker took over a wallet or hacked into a customer's account. Instead, the failure appears to have occurred during Revolut's verification of customer data requests. This makes it different from typical exchange hacking: Sensitive information can be leaked without the attacker first breaking a user's password or two-factor authentication.
This notice has been publicly shared on the X platform. As of this writing, Revolut has not issued a broader public statement or disclosed the number of accounts affected, so the scale of the incident remains unclear. Revolut customers became the target of fraudulent urgent data requests sent via emails from "government agencies."
Bitcoin records raise risk levels
CoinDesk reported that relevant materials include identification documents, account information, withdrawal records and bitcoin-related transaction history. The customer notification does not indicate that the private key, mnemonic or direct access to customer funds has been exposed.
Possible risks posed by disclosed records
Blockchain records do not contain passport details. Risk begins when a regulated platform's records link transactions to verified identities. If reported wallet references, withdrawal details, or transaction identifiers can match public on-chain activity, the association may still be useful to an attacker even after changing the account password.
Security of funds does not mean end of risk
This is not a custody violation in the ordinary sense of the word. However, detailed identity and activity profiles can support months of fraudulent contact. An attacker who knows that someone uses Bitcoin, has their contact details, and can cite real withdrawal records has a higher credibility base.
This is the same risk identified after the Bits of Gold customer data breach: Even if assets and private keys are inaccessible, identity and wallet-related records can make impersonation attempts highly convincing. Scammers do not need mnemonic words to use this information. They may ask for a one-time Captcha, claim that wallets must be moved to a "secure" address, or direct victims to legal support pages for counterfeiting. The right way to respond is to be cautious rather than rush to transfer money.
Not all Bitcoin records point to public wallets
Revolut said it maintains an internal ledger of customers 'exposure to cryptoassets. As a result, reported Bitcoin transaction history may refer to activity recorded within Revolut rather than a complete list of public blockchain addresses.
This distinction is crucial. Revolut should clarify whether the data contains external wallet addresses, transaction identifiers, destination information, or only internal account history. These situations create vastly different levels of exposure and will determine whether an attacker can easily associate a customer's true identity with visible on-chain activity.
The available evidence supports a narrower conclusion: No private key leaks have been reported, but the combination of identity files and encryption-related records described poses a unique security risk.
Measures that Revolut users can take now
Users who receive Revolut notifications should confirm through the app's support channels or directly visit Revolut's official website, rather than following links in emails or social media posts. They should ask for specific data fields that were disclosed and keep a copy of the response.
Revolut users who have not received notification need not transfer assets or assume that their data has been compromised. They should pay attention to messages within apps or notifications sent through the Revolut verification channel, review the security of restored email boxes and phone numbers, and be highly vigilant for unsolicited messages that mention cryptocurrency withdrawals or request to "protect" wallets. Changing passwords protects account access, but cannot revoke the disclosure of identity data, so the focus is on preventing impersonation rather than rushing transfers.
Anyone who is concerned that identity file data may be involved should regard unsolicited account recovery, compliance and wallet verification messages as high risk. No legitimate agent requires mnemonics, passwords, or one-time authentication codes. The European Data Protection Commission (EDPB) points out that fraud, identity theft and financial loss are among the possible consequences of personal data breaches.
The key next step is relatedness
Revolut now needs to explain whether the disclosed records contain external wallet addresses, transaction identifiers, or only internal account history. This distinction will determine whether affected customers face traditional identity fraud issues or a more lasting link between their true identities and publicly traceable Bitcoin activity.
This article is for reference only and does not constitute legal, financial or cybersecurity advice.

Exchange Ranking
Top Exchanges
24h Volume Ranking
Popularity Ranking
Exchange BTC Balance
Proof of Reserves
Decentralized Exchanges
Funding Rate
Funding Heatmap
Liquidation Data
Max Pain
Long/Short Ratio
Whale L/S Ratio
Binance/Okex/Huobi L/S
Bitfinex Margin L/S
ETF Tracker
Solana ETF
XRP ETF
Hong Kong ETF
Bitcoin Treasuries
Crypto Reversal
Ethereum Reserves
HyperLiquid Wallet Analysis
Hyperliquid Whale Watch
Large Transactions
On-chain Movement
Bitcoin ROI
Stablecoin Market Cap
Options Analysis
News
Articles
Economic Calendar
Features
Wallet
Contract Calculator
Security
Collections
Watchlist
Following
BTC